CVE-2026-5433
Honeywell Control Network Module (CNM) has a command injection flaw in its web interface that lets attackers run arbitrary commands on the device. The vulnerability can lead to full remote code execution, allowing attackers to take control of the system.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Honeywell Control Network Module (CNM) versions 100.1, 101.1, 110.1, and 110.2. Users are typically industrial control system operators and facility managers.
Real-world impact
An attacker who exploits this flaw can execute any command on the CNM, potentially taking over the device, accessing sensitive data, or disrupting industrial processes.
Why this severity
The CVSS score of 9.1 reflects that the flaw allows remote code execution with high impact on confidentiality, integrity, and availability, while the attack is easy to perform over the network and requires only high privileges on the target system.
What to do about it
- 01Update the Honeywell Control Network Module to the latest version (200.1 or later).
- 02Restart the CNM service after the update to ensure changes take effect.
NVD-referenced vendor advisory
Timeline
- May 21, 2026 · May 21, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 8d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 5d agoAdvisory updatedThe NVD record was last revised.